Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved entities in the query. It was found that an unauthorized user can manipulate an existing UDF without having the privileges to do so. This allowed unauthorized or underprivileged users to drop and recreate UDFs pointing them to new jars that could be potentially malicious.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2022-07-16T07:10:09

Updated: 2024-08-04T00:12:50.447Z

Reserved: 2021-06-10T00:00:00

Link: CVE-2021-34538

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-07-16T07:15:08.530

Modified: 2022-07-21T13:53:17.647

Link: CVE-2021-34538

cve-icon Redhat

No data.